Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: HANCITOR
- HANCITOR BUILD
- BUILD=1702_pro23
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Signature Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Service
- You received invoice from DocuSign Service
- You received notification from DocuSign Electronic Service
- You received notification from DocuSign Electronic Signature Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- MALDOC LANDING PAGE URLS
- https://docs.google.com/document/d/e/2PACX-1vQgIfA0Eba71P-4GAbtR9i4UzopM0AVx7PVI7nrYF65fUrmkjXuROsxRlQ1FVz6uOAa_9mgcwBSpEYX/pub
- https://docs.google.com/document/d/e/2PACX-1vRdIMUUkcPV2W_XHw5WBZSOGyvwkzjZ_G15YWvoTmRJh-IR4dOQKSnTxNDTv3W57vSzTRTyWAbsrWQU/pub
- https://docs.google.com/document/d/e/2PACX-1vSdAF6b9dDsWkDaM--xHUM-KzMQjYprAT0P6zhLpb_CGC-eE05dcTdX5tm5DVumDRvzCJ7XwB_XsPTq/pub
- https://docs.google.com/document/d/e/2PACX-1vT10dUghgCUkjXirdGrkZtDHfU2OFKPTpous1hQPbuH58PWWi_xmweyAyzolI6Y-evxcqrbKnN1Mo90/pub
- https://docs.google.com/document/d/e/2PACX-1vTcmrejDN5ihjM_Kc1Usu30hLGiEX1f932P2DEt_x6lQxE11EJm1o2E3sGFpUNanJcA3gsQj91tOpNZ/pub
- https://docs.google.com/document/d/e/2PACX-1vTE15GfZYtu2PXt0P_LXK4OXELVVWTVFzrLWOtU6Asrl0lHdgR_8JTwSc7-nSvk7m0yudTNGzVpqGU1/pub
- https://docs.google.com/document/d/e/2PACX-1vTqMpUzmOn4a2pgQDMYRK_CT8UUYeo0ePFKi2sPvFbHhaGvk4zrwW-RO_gb_WhzUxmJ91elxpJpKeXU/pub
- MALDOC DISTRIBUTION URLS
- http://somdeeppalace.com/slickness.php
- https://buahpinggang.my/parma.php
- https://jayins.com/disquieting.php
- https://pepselectricailservice.co.uk/archiver.php
- somdeeppalace.com
- buahpinggang.my
- jayins.com
- pepselectricailservice.co.uk
- HANCITOR MALDOC FILE HASHES
- 0b5f29fb9e3c4b2ef56af61b6046115d
- 1283f5be56f3834d8effcb6182d01dfa
- 6339d90f60316aa4df36f4dfd085d320
- ef0e5920daa89ba15bac2357bee2b502
- HANCITOR PAYLOAD FILE HASH
- W0rd.dll
- 532a355471de8f834460e026ccd65150
- HANCITOR C2
- http://hatuderefer.com/8/forum.php
- FICKER STEALER PAYLOAD URLS
- http://belcineloweek.ru/6sufiuerfdvc.exe
- FICKER STEALER FILE HASH
- 6sufiuerfdvc.exe
- 77be0dd6570301acac3634801676b5d7
- FICKER STEALER C2
- http://sweyblidian.com
- Post .doc file download phishing page (M&T Bank):
- https://webinfoplus.xn--mndtbnk-9m4ce.com/cashplus
Add Comment
Please, Sign In to add comment